Thank you!

 

From: The EDUCAUSE IT Service Management (ITSM) Constituent Group Listserv [mailto:[log in to unmask]] On Behalf Of DeFroy, Mary A.
Sent: Wednesday, June 13, 2018 10:40 AM
To: [log in to unmask]
Subject: Re: [ITSM] Governance around API usage?

 

We developed a policy for use of any API or Web Service integrations with our Remedy system.  I have attached the document.  We are transitioning to Cherwell and will be reviewing and updating this document in the near future.

Let me know if you have any questions.

 

Mary DeFroy

University of Missouri-Division of IT

Enterprise Application Services

(573) 882-4510

 

From: The EDUCAUSE IT Service Management (ITSM) Constituent Group Listserv <[log in to unmask]> On Behalf Of Wolff, Taj S
Sent: Wednesday, June 13, 2018 8:42 AM
To: [log in to unmask]
Subject: [ITSM] Governance around API usage?

 

Has anyone put together a governance policy/document around API usage in your ITSM? I am quickly realizing that we need to put something in place. We provided  an account and key to a technical person in another team for a specified integration.  Then we found that he decided to use that account and key to write an API to open/close standard changes from a command line for use by his team. The concerns we have are security of that account and key (is the key encrypted?) who has access? How do we have some control over who is accessing the system via API and for what reason.

 

If anyone has already address the governance issue, would you please share your guidelines? My thinking is that we need to have a user document and sign off on how the account/key is used and agree not to use it for any other purpose. We are currently testing whether we can grant fewer rights to that account after the API is implemented so that the key could not be reused.

 

Thanks,

Taj

Taj Wolff, MBA | Director, ITSM | Information Technology | Vanderbilt University
[log in to unmask] | phone 615.343.1621 | it.vanderbilt.edu

Did You Know? VUIT offers help, training, discounts and more at it.vanderbilt.edu 

[log in to unmask]" alt="Vanderbilt IT logo">

 

 

***************************

Visit the ITSM wiki.

***************************

Visit the ITSM wiki.

***************************

Visit the ITSM wiki.